Ransomware victim disclosure
← All victimsRS Automation Co., Ltd.
Claimed by Barracuda · listed 2 days ago
Status timeline
- ListedAug 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Barracuda
- Status
- Data leaked
- Country
- China
- Sector
- Manufacturing
- Listed on leak site
- Aug 6, 2026
About the victim
AI dossier — public-source company profileRS Automation Co., Ltd. is a South Korean manufacturer of automated wire harness and cable processing equipment, including wire cutting, stripping, crimping, twisting, and soldering machines. They serve industries including EV cable assembly and provide integrated manufacturing solutions including MES systems and AGV dispatching.
- Industry
- Industrial Machinery & Cable Processing Equipment Manufacturing
Attack summary
Severity: high — Confirmed exfiltration of significant proprietary assets including complete source code, technical specifications, and business documents from a specialized manufacturing company. The 637 GB dataset and ransom demand indicate material business disruption. No regulated PII or medical/financial data evident, placing it below 'critical' but well above 'medium'.Barracuda claims to have exfiltrated a complete dump of all company servers, developer personal files, and NAS storage totaling 637 GB. The exfiltrated data includes legal documents, correspondence, technical drawings, assembly procedures, and C/C++ source code.
Data the group says was taken
AI dossier — extracted from the leak post- source code (C/C++)
- technical drawings
- assembly procedures
- legal documents
- business correspondence
- developer personal files
What the group claims
Full dump of all files from the servers and developers personal files and NAS. Legal documents, letters, drawings, assembly, C, and C++ source codes. Official manufacturer website: rsautomation.co.kr | Status: upcoming | Size: 637 GB | Starts at $50000.00
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

